RARLAB WinRAR Command Line Processing Buffer Overflow Vulnerability
BID:15123
Info
RARLAB WinRAR Command Line Processing Buffer Overflow Vulnerability
| Bugtraq ID: | 15123 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2005 12:00AM |
| Updated: | Oct 17 2005 12:00AM |
| Credit: | [email protected] disclosed this issue. |
| Vulnerable: |
RARLAB WinRar 3.42 RARLAB WinRar 3.41 RARLAB WinRar 3.40 RARLAB WinRar 3.30 RARLAB WinRar 3.20 RARLAB WinRar 3.11 RARLAB WinRar 3.10 beta 5 RARLAB WinRar 3.10 beta 3 RARLAB WinRar 3.10 beta 3 RARLAB WinRar 3.10 RARLAB WinRar 3.0 .0 RARLAB WinRar 3.0 RARLAB WinRar 2.90 |
| Not Vulnerable: |
RARLAB WinRar 3.51 RARLAB WinRar 3.50 |
Discussion
RARLAB WinRAR Command Line Processing Buffer Overflow Vulnerability
A remote, client-side buffer overflow vulnerability has been reported in the command line processing of RARLAB WinRAR. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
A remote, client-side buffer overflow vulnerability has been reported in the command line processing of RARLAB WinRAR. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
Exploit / POC
RARLAB WinRAR Command Line Processing Buffer Overflow Vulnerability
The following exploit has been made available:
The following exploit has been made available:
Solution / Fix
RARLAB WinRAR Command Line Processing Buffer Overflow Vulnerability
Solution:
The vendor reports that versions 3.50, and 3.51 are not affected by this issue.
Solution:
The vendor reports that versions 3.50, and 3.51 are not affected by this issue.
References
RARLAB WinRAR Command Line Processing Buffer Overflow Vulnerability
References:
References:
- Vendor Home Page (RARLAB)